SC-200 Exam Question 56

You have an Azure Functions app that generates thousands of alerts in Azure Security Center each day for normal activity.
You need to hide the alerts automatically in Security Center.
Which three actions should you perform in sequence in Security Center? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

SC-200 Exam Question 57

You have an existing Azure logic app that is used to block Azure Active Directory (Azure AD) users. The logic app is triggered manually.
You deploy Azure Sentinel.
You need to use the existing logic app as a playbook in Azure Sentinel. What should you do first?
  • SC-200 Exam Question 58

    You need to assign a role-based access control (RBAC) role to admin1 to meet the Azure Sentinel requirements and the business requirements.
    Which role should you assign?
  • SC-200 Exam Question 59

    You have a Microsoft 365 subscription that uses Microsoft 365 Defender and contains a user named User1.
    You are notified that the account of User1 is compromised.
    You need to review the alerts triggered on the devices to which User1 signed in.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    SC-200 Exam Question 60

    You need to restrict cloud apps running on CLIENT1 to meet the Microsoft Defender for Endpoint requirements.
    Which two configurations should you modify? Each correct answer present part of the solution.
    NOTE: Each correct selection is worth one point.